docling
PyPI18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting doclingpage 1 of 1
- CVE-2026-105742MEDIUMCVSS 5.3EG 5.3fixed in 2.132.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (44 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forw…
- CVE-2026-105743MEDIUMCVSS 5.8EG 5.8fixed in 2.132.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (48 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hos…
- CVE-2026-105744HIGHCVSS 8.8EG 8.8fixed in 2.132.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (45 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/back…
- CVE-2026-105745HIGHCVSS 7.8EG 7.8fixed in 2.131.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (130 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setupt…
- CVE-2026-105746MEDIUMCVSS 5.3EG 5.32.131.0 (the fix for one version range)2026-10-05
vulnerable: 2.100.0 ... 2.99.0 (55 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.p…
- CVE-2026-105747MEDIUMCVSS 4.3EG 4.3fixed in 2.131.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (102 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling…
- CVE-2026-105748MEDIUMCVSS 4.3EG 4.3fixed in 2.131.02026-10-05
vulnerable: 2.100.0 ... 2.99.0 (144 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py …
- CVE-2026-105749MEDIUMCVSS 6.5EG 6.5fixed in 2.131.02026-10-05
vulnerable: 2.0.0 ... 2.99.0 (171 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/back…
- CVE-2026-105750HIGHCVSS 7.5EG 7.5fixed in 2.118.12026-10-05
vulnerable: 2.100.0 ... 2.99.0 (40 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._g…
- CVE-2026-105751MEDIUMCVSS 6.9EG 6.9fixed in 2.120.32026-10-05
vulnerable: 2.107.0 ... 2.120.2 (16 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.107.0 until 2.120.3, docling/backend/opendocument_backend.py uses the xlink:href attribute value of a dra…
- CVE-2026-31247HIGHCVSS 7.5EG 7.52026-05-11
vulnerable: 0.1.0 ... 2.9.0 (137 versions)
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nest…
- CVE-2026-31248HIGHCVSS 7.5EG 7.52026-05-11
vulnerable: 0.1.0 ... 2.9.0 (137 versions)
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can cr…
- CVE-2026-44016HIGHCVSS 8.2EG 8.2fixed in 2.91.02026-06-03
vulnerable: 2.82.0 ... 2.90.0 (9 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option …
- CVE-2026-44017HIGHCVSS 7.5EG 7.5fixed in 2.91.02026-06-03
vulnerable: 0.1.0 ... 2.90.0 (171 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP archives without validating member paths…
- CVE-2026-44018HIGHCVSS 7.1EG 7.1fixed in 2.91.02026-06-03
vulnerable: 2.45.0 ... 2.90.0 (55 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked secu…
- CVE-2026-44020HIGHCVSS 7.5EG 7.5fixed in 2.74.02026-06-03
vulnerable: 2.13.0 ... 2.73.1 (84 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString() without protection…
- CVE-2026-44022MEDIUMCVSS 5.5EG 5.5fixed in 2.91.02026-06-03
vulnerable: 2.73.0 ... 2.90.0 (19 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked …
- CVE-2026-47214HIGHCVSS 7.1EG 7.1fixed in 2.94.02026-06-03
vulnerable: 0.1.0 ... 2.93.0 (174 versions)
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
Check whether docling is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for docling CVEs against the assets you own.
Book a Demo →